Impact
The description indicates a race condition involving a shared resource in the Remote Desktop Client that permits an unauthorized attacker to execute code over a network. The exploitation occurs with the privileges of the client process, potentially granting full control of the affected system.
Affected Systems
Affected are the Remote Desktop client for Windows Desktop and its Windows App Client, as well as all listed Windows 10 and Windows 11 releases from version 1607 to and the corresponding Windows Server versions from 2012 to 2025. The vulnerability spans both x86 and x64 architectures, including ARM64 for newer Windows 11 builds.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of < 1% indicates a very low but nonzero exploitation probability. The lack of a KEV listing does not diminish the risk: the vulnerability can be exploited remotely over the network by an unauthorized actor. The likely attack vector is a network-based Remote Desktop session, where the attacker malicious packets to trigger the race condition and achieve remote code execution. The impact on confidentiality, integrity, and availability is significant, as full system control can be obtained without user interaction.
OpenCVE Enrichment